Who Is Really Responsible for Cybersecurity in an Organisation?

  • 2026-10-01
  • Viesturs Bulāns, CEO and Partner of Helmes Latvia

The summer in Latvia passed under a red alert for cybersecurity. Fraudsters and cyber attackers continued to exploit both technological vulnerabilities and human error. According to CERT.LV data, in the second quarter of 2026, more than 8% of cyberattacks had a significant impact, while more than 5% had a broader impact on businesses, state institutions or local authorities. Cyberspace has become an arena for strategic competition between states and for hybrid warfare activities. Geopolitical tensions, including Russia’s war against Ukraine and conflicts in other regions of the world, are also reflected in the cyber domain, affecting both the intensity of attacks and the methods used. These trends also affect Latvia, where the nature of cyber threats is increasingly shaped by developments in the international security environment.

Cybersecurity is no longer a theoretical future risk or a problem affecting only large international corporations. It is an everyday reality that both the public and private sectors must address. Yet when we talk about cybersecurity within a company or organisation, we still tend to automatically look towards the IT department or IT service provider. This approach is outdated – and potentially dangerous.

Cybersecurity is an organisational risk management issue

Today, the core processes of almost every organisation depend on technology in one way or another – from customer and employee data to payments, supply chains, production and communications. A cyber incident is therefore not merely a technical problem. It can bring an organisation’s operations to a halt, cause financial losses, trigger a reputational crisis, result in personal data breaches and, in some cases, jeopardise the continuity of services that are essential to society.

Cybersecurity must therefore be treated as an organisational risk management issue.

Section 25(1) of Latvia’s National Cyber Security Law establishes that the head of an organisation is responsible for ensuring and managing its cybersecurity. The same section requires the head of the organisation to appoint a responsible person – a cybersecurity manager – to implement and oversee cybersecurity measures. It is important to understand the distinction. A cybersecurity manager or IT specialist may have professional responsibility for implementing specific measures, protecting systems, identifying risks and responding to incidents, but the head of the organisation cannot delegate the ultimate responsibility for cybersecurity governance. In much the same way, a company executive cannot simply claim that financial risks are solely the responsibility of the accountant.

Cybersecurity requires resources

The law also sets out the responsibilities of the cybersecurity manager. These include organising security measures for the organisation’s ICT infrastructure, carrying out ICT security assessments and coordinating the remediation of identified vulnerabilities, as well as ensuring that employees receive regular training on current cyber risks and cybersecurity practices. However, fulfilling these responsibilities requires resources. Cybersecurity must be given sufficient priority, and that decision ultimately rests with management. If a security specialist identifies a critical system vulnerability but the organisation postpones the necessary investment for years, this is no longer simply an IT issue – it is a business risk created by management decisions.

Cybersecurity must be on the management agenda

Across the European Union, cybersecurity has increasingly been approached as a matter of organisational resilience and governance. This has been reinforced in particular by the NIS2 Directive, which aims to achieve a high common level of cybersecurity across the EU. One of the most significant changes introduced by this approach is the increased emphasis on the role of management. Management bodies are expected to approve cybersecurity risk-management measures and oversee their implementation. This means cybersecurity must become a regular item on the management agenda, alongside financial risks, legal matters and other strategic issues. It is no longer sufficient to ask during a management meeting or a conversation with an IT service provider whether “everything is fine with security”. Organisational leaders need to know where their most critical data and systems are located, what the potential consequences would be if those systems became unavailable, and how quickly the organisation could restore its operations.

Responsibility must extend across every level of the organisation

At the same time, it would be equally misleading to say that cybersecurity is solely the responsibility of management. In practice, effective cybersecurity depends on responsibilities being clearly distributed across all levels of an organisation. Management is responsible for governance, priorities and resources. Cybersecurity and IT professionals are responsible for professional risk management and technical solutions. Every employee, meanwhile, is responsible for their own behaviour in the digital environment. Even an organisation with highly sophisticated technical protection can still be compromised by a single convincing phishing email, a weak password, an unchecked attachment or a payment approved in haste. People are therefore both a potential point of vulnerability and one of the organisation’s most important lines of defence.

The importance of employee training

This is precisely why employee training plays such an important role. Sending out an e-learning course once a year and asking employees to complete a short quiz afterwards does not, by itself, create a cybersecurity culture. Employees need to understand not only that they should avoid clicking suspicious links, but also why particular actions can be dangerous, how to recognise increasingly sophisticated fraud attempts, and what to do when a mistake has already been made. In an organisation where employees are afraid to report that they have opened a suspicious attachment or entered their password on a fraudulent website, critical minutes – or even hours – can be lost. 

A strong security culture therefore also means creating an environment in which employees are not afraid to report incidents. It is equally important to remember that absolute security is impossible. An incident can occur even in the best-protected organisation. Cybersecurity maturity should therefore not be measured simply by the number of security technologies a company has purchased. Far more important questions are: Do we understand our most critical risks? Can we detect an incident quickly enough? Do employees know whom to notify? Does management know what to do in a crisis? And can we restore operations quickly enough after an attack? 

The answer to the question “Who is responsible for cybersecurity in an organisation?” cannot be reduced to a single job title. Management is responsible for cybersecurity governance and ensuring that adequate resources are available. The cybersecurity manager, IT team or IT service provider is responsible for professional and technical implementation. And every user of the organisation’s systems is responsible for secure behaviour in their daily work. Cybersecurity, in other words, is a shared responsibility – but it starts at the top.